Impact
A missing authorization check in the FileSystem API of Google Chrome allows an attacker who has already compromised the renderer process to read or write files accessible to that process via a crafted HTML page. The flaw is a CWE-862 access control weakness that may expose sensitive data but does not directly provide code execution. The vulnerability can be triggered only after the attacker obtains renderer compromise, typically through social engineering or a separate flaw.
Affected Systems
Affected product: Google Chrome versions prior to 152.0.7977.75. The issue resides in the FileSystem API implemented within the Chrome renderer component; all installations of Chrome below the specified patch level are potentially vulnerable.
Risk and Exploitability
Chromium’s internal severity rating is Medium, with a CVSS score of 5.3 indicating a moderate impact. The EPSS score is not available and the vulnerability is not in the CISA KEV catalog. Exploitation requires first compromising the renderer process, which can be achieved via a separate vulnerability or social engineering tactics, followed by delivering a malicious HTML payload that utilizes the unprotected FileSystem API. Because the attack chain depends on a prior compromise, the likelihood of widespread exploitation is limited, but within target environments that allow users to run HTML pages, the risk of data exfiltration remains present.
OpenCVE Enrichment
Debian DLA
Debian DSA